Re: Hide Include-Files from the Web

From: Date: Sat, 03 Mar 2001 12:58:36 +0000
Subject: Re: Hide Include-Files from the Web
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-42442@lists.php.net to get a copy of this message
Include files do not have to end with '.inc', which is purely a convention of dubious value. If you use '.php' as the extension for included files, they will have to be parsed by PHP and can't be read as plain text from outside. Mick On Sat, 3 Mar 2001 mailing_list@gmx.at wrote: > Hi! > > I want my include-files not be seen from outside AND not be executed!!! > I don't have access to a directory outside DOCUMENT_ROOT and I don't have > .htaccess!!! > > I think about something like: > 1. > name: <file>.inc.php > 2. > add code: > if ($PHP_SELF==MY_NAME) exit; > as first line in the inluded script. > so, if the script is being included from another script, the code will be > executed - but if the file will be called directly, no code is executed! > BUT - how do I get the include-file's name? > > or is it safe enough, to use something like > if (substr($SCRIPT_URL,-8)==".inc.php") exit; > > thanks > michi > > -- > Sent through GMX FreeMail - http://www.gmx.net > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#42442) next »